Password Reuse Tool Makes It Easy To ID Vulnerable Accounts On Other Sites (arstechnica.com)
Dan Goodin, reporting for Ars Technica: Over the past few months, a cluster of megabreaches has dumped account credentials for a mind-boggling 642 million accounts into the public domain, where they can then be used to compromise other accounts that are protected by the same password. Now, there's software that can streamline this vicious cycle by testing for reused passcodes on Facebook and other popular sites. Shard, as the command-line tool has been dubbed, is designed to allow end users to test if a password they use for one site is also used on Facebook, LinkedIn, Reddit, Twitter, or Instagram, its creator, Philip O'Keefe, told Ars. The security researcher said he developed the tool after discovering that the randomly generated eight-character password protecting several of his accounts was among the more than 177 million LinkedIn passwords that were leaked in May. "I used that password as a general password for many services," he wrote in an e-mail. "It was a pain to remember which sites it was shared and to change them all. I use a password manager now."
How many people in the US have to die before we realize that private ownership of guns is terrible idea?
You don't need a gun. If you have one, you can dispose of it at any police station, no questions asked.
Lets use a tool that sends a known password to a whole bunch of sites to see if it works there. What could possibly go wrong?
This idea is fundamentally flawed.
Black lives do matter! Mod this post up to support equality and an end to unwarranted harassment and violence by law enforcement. There are a disproportionate amount of fatal police shootings of black people. Furthermore, a disproportionate amount of those black people shot and killed by police were unarmed. It's not acceptable that an unarmed black person is more likely to be killed an unarmed person with a different skin color? Please mod this post up to show your support for responsible and fair policing and that you believe black lives do matter.
A security researcher didn't already use a password manager? That, 8-character password, and password reuse doesn't inspire confidence in the tool he wrote...
This country is coming apart. We are in the midst of a full-blown race war and all kinds of crazies are running around with AK47 machine guns like this is Pakistan. I hoped that the election of Barak Obama would lead to better race relations but everything has gotten worst since he was elected. I think we are headed for a second civil war.
On a list. Haha
Facebook records the passwords used in your failed login attempts. If you forgot which of your passwords is used on a given site, you are potentially divulging your passwords to many sites. Facebook may not be alone in this.
the randomly generated eight-character password protecting several of his accounts was among the more than 177 million LinkedIn passwords that were leaked in May
Either he was part of the leak, and then it doesn't matter how long and strong his password was, only that he reused it (and the site did not salt enough); or it was someone else's password too by chance, but then it wasn't random, by at least three orders of magnitude, if it was found among ~2E8 "random" passwords.
Every end has half a stick.
These days there's dozens if not hundreds of sites you can "sign in with" trivially, but so few support anything more than perhaps Facebook.
Just avoid passwords entirely: Let one of the big movers/shakers handle your user auth, stop creating accounts yourself. XD
"The security researcher said he developed the tool after discovering that the randomly generated eight-character password"
Wait, what do you mean he "discovered" this? Doesn't this "researcher" know what his own fucking passwords are?
-
"I used that password as a general password for many services," he wrote in an e-mail.
What he meant to say was, "I claim to be a security researcher but really I'm just a hypocritical idiot who doesn't practice what I preach."
Just cruising through this digital world at 33 1/3 rpm...
As I don't have an account with Facebook, LinkedIn, Reddit, Twitter, nor Instagram, I should be fine then.
/. karma.
I use the same login here, at Soylent, Fark, Ars, and a couple others I can't think of off the top of my head. Guess what? I use the same password too. Why? I don't care if someone steals my
My banks and anyone with my credit card #? You bet they all have different logins and passwords, for which I use keepass to manage.
Seems like a more useful solution for most ppl since you want to trust the thing you give all your passwords to .. . a lot. Plus the fact that ppl might actually use it if LastPass or Google do it.
Google can just implement it right in their password sync feature.
Or just start using Lastpass...
TBH i didn't get how this software works. You type the password and it checks it against a few sites? Thats it? That would be incredibly ineffective...
I have over 100 sites and passwords on my Lastpass Vault and it can tell me where and what passwords are currently being reused.
Right there. What an idiot.
but its random and very hard to remember!